pCloud.exe

WpfpCloud

pCloud LtD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘pCloud’.
Publisher:
pCloud LtD  (signed and verified)

Product:
WpfpCloud

Version:
1.0.0.0

MD5:
6b6ecd7d4ae0eed9e49f2757eb901a4d

SHA-1:
e03ff2d3185835e52dbae02914155cc0ecedf81d

SHA-256:
8a4e949ab162fe6a65082b0f8bd4c8462bd1f66298b37aafd7aad1e703425baa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:33:47 PM UTC  (today)

File size:
1.6 MB (1,696,016 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
pCloud.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\pcloud\pcloudsync\pcloud.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/12/2013 4:30:00 AM

Valid to:
9/13/2015 4:29:59 AM

Subject:
CN=pCloud LtD, O=pCloud LtD, STREET="17 Akad. Boris Stefanov, Floor 1, Office (apt) 2", STREET=Stiudentski grad district, L=Sofia, S=Sofia, PostalCode=1700, C=BG

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0C1F075DF8FA65D5A3601601C61FAF7E

File PE Metadata
Compilation timestamp:
4/11/2014 4:14:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:4G5sg8fJG18mTHK9PIVX68iABTPt05CfIK4HxYh+JkrZ:4GOg8018mTHK9PIlpdPt05CfIK4RYhR

Entry address:
0x19EA2E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.8075

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.6 MB (1,690,624 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
pCloud

Command:
C:\Program Files\pcloud\pcloudsync\pcloud.exe


Scan pCloud.exe - Powered by Reason Core Security